PingOne Single Sign-on (SSO) Setup Guide

  • Updated

Zingtree supports SAML 2.0 based Single Sign-on (SSO). This lets you require anyone accessing a tree to log in via your Identity Provider and authenticate themselves first. This article will walk you through how to set it up using Salesforce. 

 

Setup

Zingtree allows you to set up SSO for the Author and Agent roles. This example will follow setting up SSO for Authors, but the process is exactly the same for agents. 

  1. Begin by logging in to your PingOne administrator portal and click connections from the menu on the left. 

    Step_1.png

  2. Choose Applications from the side menu and then at the top of the page click the Plus (+) icon.

    Step_2.png

  3. You'll need to fill out the Application Name and Description. In this example we are setting SSO for our Authors so we are naming this application Zingtree Authors.  Under Choose Application Type make sure you choose SAML Application. When you're done click Save

    Step_3.png

  4. Log in to your Zingtree Account and go to Account Settings > Single Sign-on (Zingtree will look a little different depending on which version you're using).

    Classic:

    Step_4.png

    New Authoring:

    Step_4_Z2.png

  5. You can use the Orange button to toggle between setting up Single Sign-on for your Authors or Agents. You will need the Login (ACS) URL and the Entity ID.

    Step_5.png

  6. In PingOne, choose the Manually Enter option and then paste in the ACS URL and the Entity ID.

    Step_6.png

  7. In PingOne select the Zingtree App from your applications page and then click Download Metadata. 
    Step_7.png

  8. From the Metadata information find the Entity ID, ACS URL, and Certificate. In Zingtree click the Next: Enter Identity Provider Data for Authors/Agents button and paste the information in the corresponding fields. You'll also need to tick the box to enable Multi-factor Authentication (MFA). If you don't you will get SSO error messages. 
    Step_8.png


  9. Back in PingOne we need to assign users to the Zingtree Authors app we set up. Choose the Identites option from the menu on the left. 

    Step_9.png

  10. Select Users and then Add User. We'll Add all of the Authors who need access to Zingtree. 

    Step_10.png

  11. Now we'll go to the Groups tab and click the Plus (+) icon to set up a group called Zingtree Authors. We're going to name the group Zingtree Authors. 

    Step_13.png

Once the group is created we can click the icon and then select the Users tab. From here we'll add all of the Authors we previously added to the group. 

Step_14.png

Testing

 

To test the connection do the following: 

  1. In Zingtree click the Test Author/Agent Login Button. 

 

Enabling SSO for Agents/Authors

Once SSO is working properly from your test, you can restrict access to any tree as follows.

  1. From Account, Single Sign-on, make sure you are on the Agents/Authors page.
  2. Tick enable Agents/Authors.

    SFSSO17.png

IMPORTANT: You still need to specify individual trees to restrict access to. Here’s how:

  1. Go to My Trees, and select the tree that you want to require SSO login.
  2. Click Settings > Security, and you’ll see something like this:

    2022-05-05_10-21-53.png

  3. Check Require Login via Single Sign-on (SSO).
  4. Click Update Settings.

Dedicated Agent Login

Rather than having Agents go through the Zingtree login page, you can send them directly to your SSO login page. Here’s how:

    1. Go to Account, My Agents.
    2. Give your agents the link from this button:

      img_5a46a5f9d3970.png



Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request

Didn't find what you need?

Our friendly customer support team is here to help

Submit a Ticket

Looking for help or advice?

Reach out to our knowledgeable community of users.

Zingtree Community